Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2020-13656] OOB to RCE: Exploitation of the Hobbes Functional Interpreter

Summary

Jake Miller details CVE-2020-13656 in Morgan Stanley's Hobbes interpreter: missing array bounds checking yields an out-of-bounds read/write primitive leading to local and remote code execution.
Published
Collected

original ↗

Related coverage

back